Inspiration
Modern Security Operations Centers (SOCs) suffer from extreme alert fatigue—analysts face thousands of daily warnings, with false positive rates exceeding 70%. Real threats often drown in the noise, leading to delayed responses and burnout. We were inspired by the idea of an AI "co-pilot" that doesn't just flag anomalies, but actively thinks like a tier-3 analyst. We envisioned ThreatPulse: a system that reads raw telemetry, understands adversarial tactics, and delivers actionable intelligence in plain English, slashing Mean Time to Detection (MTTD) from hours to minutes.
What I Learned
This project was a deep dive into the intersection of Generative AI and Cyber Defense.
- Prompt Engineering is critical: Designing few-shot prompts with MITRE ATT&CK context dramatically improved the LLM's ability to map events to specific TTPs (Tactics, Techniques, and Procedures).
- Data normalization is the hidden bottleneck: SIEM logs vary wildly across vendors. We learned to build a lightweight parsing layer that extracts unified fields (source IP, user, action) before feeding the LLM.
- Explainability is non-negotiable: For a SOC analyst to trust an AI verdict, the system must provide audit trails. We implemented a reasoning-chain logger that justifies every action, satisfying compliance requirements like GDPR and HIPAA.
- Mathematically, we optimised the risk prioritisation formula: $$ \text{Risk_Score} = \text{CVSS_Base} \times \text{Business_Criticality} \times \text{Confidence_LLM} $$ where $$ \text{Confidence_LLM} $$ is derived from the model's token probability distribution over the predicted attack class.
How I Built It
We built ThreatPulse as a modular, cloud-native microservice:
- Data Ingestion: Used Apache Kafka to stream live logs and Elasticsearch for historical querying.
- Core Intelligence: Deployed a quantised Mistral-7B model via Ollama to ensure on-premise data privacy (no sensitive logs leave the customer's network). We used LangChain for agentic orchestration, connecting the LLM to a vector database (Pinecone) containing CVE descriptions and exploit databases.
- Backend: FastAPI (Python) handles RESTful endpoints and webhook integrations with Slack and Jira.
- Frontend: Built a real-time dashboard with React and D3.js to visualise attack chains as interactive kill-chain graphs.
- Automation: The system generates Python scripts via the LLM to run specific firewall block commands (validated in a sandbox) and pushes them to the EDR (Endpoint Detection and Response) tool.
# Example logic flow
def triage_alert(raw_log):
entity = extract_entities(raw_log)
context = retrieve_similar_incidents(entity)
prompt = build_prompt(entity, context)
decision = llm.invoke(prompt)
if decision.confidence > 0.85:
execute_playbook(decision.action)
return decision
Log in or sign up for Devpost to join the conversation.